Logback 1.5.36
2026-06-25 Release of logback version 1.5.36
• The 'condition' attribute in <if> elements now reject certain references that are associated with ACE attacks. This issue was reported by "yulate" (yulate531@gmail.com.com) and registered as CVE-2026-13006.
• A bitwise identical binary of this version can be reproduced by building from source code at commit 9b94c37562bf25a6a944146701d42ee6c4eee888 associated with the tag v_1.5.36. Release built using Java "21" 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.
v3.5.16
- Upgrade to Spring AMQP 3.2.12 #50818
- Upgrade to Spring Data Bom 2025.0.13 #50819
- Upgrade to Spring Integration 6.5.10 #50820